Time left: 1:11
An attacker successfully obtained all credit card information of a company's customers by following these steps:
1. The attacker found that a web server was vulnerable to XSS.
2. The attacker used the "Contact Us" web form to introduce JS code that downloads malware.
3. When reviewing the message, the administrator's computer was infected by a keylogger.
4. The keylogger captured the administrator's credentials, which were sent to the attacker.
5. The attacker used the credentials to access the web application with administration privileges and obtain confidential information about the company's customers.
Match each step with the corresponding action:
Step 1: Reconnaissance
Step 2: Exploitation
Step 3: Expansion Damage
Step 4: Exfiltration
Step 5: Choose.